Ransomware victim disclosure
← All victimsCMPM Group
Claimed by Genesis · listed 6 hours ago
Status timeline
- ListedAug 19, 2026
Current state: Negotiating
At a glance
- Group
- Genesis
- Status
- Negotiating
- Sector
- Healthcare
- Listed on leak site
- Aug 19, 2026
About the victim
AI dossier — public-source company profileCMPM Group is a healthcare organization that operates or manages more than 20 medical facilities across multiple specialties including cardiology, diabetes and endocrinology, infectious disease, rheumatology, and internal medicine. The group appears to be based in or around Memphis, Tennessee, based on facility names listed in the breach disclosure.
- Industry
- Healthcare Services & Medical Practice Management
Attack summary
Severity: critical — Confirmed exfiltration of healthcare patient data at scale (20+ medical facilities) constitutes regulated sensitive personal health information (PHI). Healthcare data breaches of this magnitude involving multiple specialties and patient populations meet critical severity thresholds.Genesis claims to have exfiltrated data from CMPM Group's systems, which store patient records from over 20 affiliated medical facilities. The group states that negotiation efforts have stalled due to communication issues, incompetent recovery response, or indifference from the victim organization. No specific ransom demand or figure is stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- patient medical records
- healthcare data from 20+ facilities
- personal health information
What the group claims
A healthcare organization that stores data from more than 20 medical facilities. A negotiator from the company contacted the ransomware group but has not taken reasonable action. The group is threatening to publish full breach details, file tree, and data. Member companies include: Cardiology Group of CMPM, AM Diabetes & Endocrinology Center, Endocrinology Associates of Memphis, CMPM Imaging Center, Mid City Medical Associates, Threlkeld Infectious Disease, Memphis Internal Medicine and Pediatrics, Memphis Cardiovascular Center, Memphis Arthritis & Rheumatology Clinic, Mary Margaret Hurley MD, Hanissian Healthcare, Hanissian Allergy, G2Endo, Engbretson Center for Women, Allmon Internal Medicine, Endocrine and Diabetes Specialists, Endocrine & Diabetes Clinic, Edward Muir MD, East Memphis Internal Medicine, Cresthaven Internal Medicine, Complete Health Care Center, Collierville Medical Specialists.
The leak post
captured from the group's site**Full details about the breach, a list of affected companies, the file tree, and the data itself will be published in:** A healthcare organization that stores data from more than 20 medical facilities. A negotiator from that company contacted us. In the past few weeks, he hasn’t done anything reasonable. So either they have communication issues, or they’ve turned to an incompetent recovery team, or they simply don’t care about the massive amount of data they’re supposed to protect. It’s not even clear which of those is worse. ``` Data details will be disclosed soon. ``` **List of companies in CMPM Group:** ``` Cardiology Group of CMPM AM Diabetes & Endocrinology Center Endocrinology Associates of Memphis CMPM Imaging Center Mid City Medical Associates Threlkeld Infectious Disease Memphis Internal Medicine and Pediatrics Memphis Cardiovascular Center Memphis Arthritis & Rheumatology Clinic Mary Margaret Hurley, MD Hanissian Healthcare Hanissian Allergy G2Endo Engbretson Center for Women Allmon Internal Medicine Endocrine and Diabetes Specialists Endocrine & Diabetes Clinic Edward Muir, MD East Memphis Internal Medicine Cresthaven Internal Medicine Complete Health Care Center C…
Screenshot of the leak post

Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

